Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now

DEVMAN

176
Global rank
147 infographic chevron month
Month rank
113 infographic chevron week
Week rank
0
IOCs

DEVMAN is a fast-evolving malware family targeting Windows environments with a mix of credential theft, remote control capabilities, and persistence techniques typical of modern crimeware. Initially observed in early 2025, DEVMAN quickly became a favorite tool among cybercriminal groups thanks to its stealth, modular structure, and ability to bypass traditional AV solutions.

Ransomware
Type
Unknown
Origin
1 April, 2025
First seen
28 August, 2026
Last seen

How to analyze DEVMAN with ANY.RUN

Type
Unknown
Origin
1 April, 2025
First seen
28 August, 2026
Last seen

IOCs

IP addresses
135.232.92.97
48.209.6.48
2.16.106.32
74.179.77.204
23.50.186.53
172.211.123.249
20.190.160.20
48.192.1.64
48.209.138.189
23.216.155.168
23.11.41.157
23.52.181.212
34.160.81.0
140.82.121.5
2.20.114.100
48.209.133.15
150.171.22.17
20.165.94.46
92.223.97.79
135.233.95.144
Hashes
4f92e804a11453382ebff7fb0958879bae88fe3366306911dec9d811cd306eed
a0c9abae18599f0a65fc654ad36251f6330794bea66b718a09d8b297f3e38e87
41c91a9c93d76295746a149dce7ebb3b9ee2cb551d84365fff108e59a61cc304
e2610960c3757d1757f206c7b84378efa22d86dcf161a98096a5f0e56e1a367e
ace9875fef7e1426d3590993377bc2e4af93c1c323a00266cdca240e91c0c82a
e4f60d0aa6d7f3d3b6a6494b1c861b99f649c6f9ec51abaf201b20f297327c95
2a6bb3bc75e9377414701bcf5887dd4e1b59803d717c9f7ff57100c5eeba3ef7
bb0885d1f6f81f14d725c099f4cc49560d25ecb40cc9e7286710c3cb20790ef3
92b3a0a230bbc2fa58e67e9ea3c4ac4e5296e3fe957049d3d24ed536409b1008
f5622bd989ba85f22f123566aa1d8d1876180d72faee6b3a38fa47da754f65ac
1bccbca62017238098fda7509c78476712c38fe05cfa6e3fbd8c087658800d6e
5793eebdb828cb9e79272560baf2b90392a8a1e796c4699d7dbd97f2edabb116
0bff302973818fc673497685bc344fc958b3829158ffe8e83c5db87ed63e0090
1533c06f0d9d9cd6be3baeb5268ce3c912aa68d164f71f10c64c8e795d792936
0be855a158090ac4e15abc0cf6d589743632ae5b64898435a660fa8188c24603
41c5d833213d394d22a046897d33aa06d0ed704326797f8ddbdaad9bd0026f91
539147c329e3697c8360574e26691c38d70d3bc49a6adcd097420d70c1e60821
6028bd681dbf11a0a58dde8a0cd884115c04caa59d080ba51bde1b086ce0079d
f7b24f2eb3d5eb0550527490395d2f61c3d2fe74bb9cb345197dad81b58b5fed
fbcfe23a2ecb82b7100c50811691dde0a33aa3da8d176be9882a9db485dc0f2d
Domains
www.bing.com
api.github.com
ocsp.digicert.com
config.edge.skype.com
settings-win.data.microsoft.com
login.live.com
slscr.update.microsoft.com
fe3cr.delivery.mp.microsoft.com
msedge.api.cdp.microsoft.com
www.microsoft.com
client.wns.windows.com
google.com
activation-v2.sls.microsoft.com
go.microsoft.com
crl.microsoft.com
self.events.data.microsoft.com
nexusrules.officeapps.live.com
msedge.f.tlu.dl.delivery.mp.microsoft.com
o4504977150377984.ingest.sentry.io
oneocsp.microsoft.com
URLs
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=1&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
https://settings-win.data.microsoft.com/settings/v3.0/onesettings/client?osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&localdeviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&attrdataver=186&osuilocale=en-us&osskuid=48&app=wosc&appver=&isflightingenabled=0&telemetrylevel=1&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/flightsettings/fsservice?processorclockspeed=3094&isretailos=1&oemmanufacturername=dell&flightingpolicyvalue=3&enablepreviewbuilds=4294967295&osversionfull=10.0.19045.4046.amd64fre.vb_release.191206-1406&managepreviewbuilds=3&branchreadinesslevelsource=0&attrdataver=186&processorcores=6&branchreadinesslevelraw=16&totalphysicalram=6144&tpmversion=0&oemmodelnumber=dell&systemvolumetotalcapacity=260281&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&app=fss&appver=10.0&smartactivehoursstate=1&activehoursstart=20&securebootcapable=0&activehoursend=13&devicefamily=windows.desktop
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?processorclockspeed=3094&flightids=&updateoffereddays=4294967295&branchreadinesslevel=cb&oemmanufacturername=dell&isclouddomainjoined=0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&sku=48&activationchannel=retail&attrdataver=186&ismdmenrolled=0&processorcores=6&processormodel=amd%20ryzen%205%203500%206-core%20processor&totalphysicalram=6144&primarydisktype=4294967295&flightingbranchname=&chassistypeid=1&oemmodelnumber=dell&systemvolumetotalcapacity=260281&sampleid=95271487&deviceclass=windows.desktop&app=muse&disabledualscan=0&appver=10.0&oemsubmodel=j5cr&locale=en-us&isalwaysonalwaysconnectedcapable=0&ms=0&defaultuserregion=244&updateserviceurl=http%3a%2f%2fneverupdatewindows10.com&osver=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceid=s%3abad99146-31d3-4ec6-a1a4-be76f32ba5d4&deferqualityupdateperiodindays=0&ring=retail&deferfeatureupdateperiodindays=30
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://config.edge.skype.com/config/v1/edgeupdate/1.3.257.13?clientid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&appchannel_edgeupdate=6&appconsentstate_edgeupdate=0&appdayofinstall_edgeupdate=0&appinactivitybadgeapplied_edgeupdate=0&appinactivitybadgecleared_edgeupdate=0&appinactivitybadgeduration_edgeupdate=0&appinstalltimediffsec_edgeupdate=0&appispinnedsystem_edgeupdate=false&applastlaunchcount_edgeupdate=0&applastlaunchtime_edgeupdate=0&applastlaunchtimejson_edgeupdate=0&applastlaunchtimedaysago_edgeupdate=0&appversion_edgeupdate=1.3.257.13&appupdatecheckisupdatedisabled_edgeupdate=false&appupdatesallowedformeterednetworks_edgeupdate=false&hwdisktype=2&hwhasssse3=true&hwlogicalcpus=6&hwphysmemory=6&isctadevice=false&ismsftdomainjoined=false&oemproductmanufacturer=dell&oemproductname=dell&osarch=x64&osisdefaultnetworkconnectionmetered=false&osisinlockdownmode=false&osiswip=false&osplatform=win&osproducttype=48&osversion=10.0.19045.4046&requestcheckperiodsec=-1&requestdomainjoined=false&requestinstallsource=otherinstallcmd&requestismachine=false&requestomahashellversion=1.3.257.13&requestomahaversion=1.3.257.13
https://msedge.api.cdp.microsoft.com/api/v2/contents/browser/namespaces/default/names?action=batchupdates
https://msedge.api.cdp.microsoft.com/api/v1.1/internal/contents/browser/namespaces/default/names/msedgewebview-stable-win-x64/versions/152.0.4191.53/files?action=generatedownloadinfo&foregroundpriority=true
http://msedge.f.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/4e34eec8-a0b7-4300-8b81-27ac4076cd47?p1=1788543862&p2=404&p3=2&p4=i4eajx7j9e3819k8w%2bahqz%2fn8zcukqjnapr60cmgql4ssj0zvwdfds3kyf8ze4rony4%2f0orj7vczvunx2lnlpw%3d%3d
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/rst2.srf
https://login.live.com/ppsecure/deviceaddcredential.srf
https://settings-win.data.microsoft.com/settings/v3.0/wsd/updatehealthtools?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=s:bad99146-31d3-4ec6-a1a4-be76f32ba5d4&sampleid=s:95271487&appver=10.0.19041.3626&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=sedimentpack&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20product%20root%20certificate%20authority%202018.crl
http://www.microsoft.com/pkiops/crl/microsoft%20ecc%20update%20secure%20server%20ca%202.1.crl
https://slscr.update.microsoft.com/sls/%7b522d76a4-93e1-47f8-b8ce-07c937ad1a1e%7d/x64/10.0.19045.4046/0?ch=686&l=en-us&p=&pt=0x30&wua=10.0.19041.3996&mk=dell&md=dell
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
https://slscr.update.microsoft.com/sls/ping
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 3496
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 9012
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 11690
comments 0

From Conti Clone to RaaS King: DEVMAN’s 2025 Rampage Exposed

Key Takeaways

  1. Global Reach, Regional Focus: Over 120 victims since April 2025, hitting Asia/Africa hardest but sparing no sector except pediatric care.
  2. Double-Extortion Mastery: Pairs encryption with massive exfiltrations (e.g., 2.5 TB), scaling ransoms to millions for high-revenue targets.
  3. Code Reuse Fuels Speed: DEVMAN's DragonForce/Conti foundations enable rapid deployment but introduce bugs like self-encrypting notes, exploitable for detection.
  4. SMB and GPO Propagation: Relies on network shares and policies for stealthy spread, bypassing traditional perimeter defenses.
  5. RaaS Democratization: DEVMAN 2.0's affiliate model (78-93% cuts) floods the market with attacks, requiring ecosystem-wide vigilance.
  6. Leverage Threat Intelligence Lookup for Proactive Defense: Services like ANY.RUN’s TI Lookup aggregate real-time IOCs and TTPs from DEVMAN's malware samples, empowering teams to block threats before encryption hits. Search by the ransomware’s name to explore sandbox analysis sessions and gather indicators.

threatName:"devman".

DEVMAN sandbox analyses DEVMAN sandbox analyses with IOCs and TTPs

  1. ANY.RUN's Interactive Sandbox provides unparalleled visibility into DEVMAN's complex behaviors through real-time logging of file system changes, registry modifications, and mutex creation. The platform's interactive analysis capabilities enable security teams to investigate unusual variants, extract comprehensive IOCs, and understand threat evolution — critical advantages when defending against rapidly changing ransomware families like DEVMAN.

View analysis

DEVMAN sample in the Sandbox DEVMAN malware detonated in ANY.RUN’s Sandbox

What is DEVMAN Ransomware?

DEVMAN ransomware emerged in early 2025 as a sophisticated threat that shares its genetic code with two notorious predecessors: DragonForce and Conti. This ransomware uses the .devman file extension for encrypted files and evolved from DragonForce code, representing a new chapter in the ongoing evolution of ransomware-as-a-service operations. It has proven to be a persistent and evolving threat with over 120 documented victims across multiple continents.

The malware implements three distinct encryption modes: full encryption for comprehensive data corruption, header-only encryption for speed optimization, and custom encryption for targeted scenarios. This flexibility allows attackers to balance speed against thoroughness depending on their objectives.

The ransomware operates almost entirely offline, with no external command-and-control communication observed during analysis. Instead, it relies on local SMB probing to facilitate lateral movement within compromised networks. DEVMAN creates a temporary session under the registry key HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 to bypass file locks, a technique inherited from its Conti lineage that enables encryption of active user session files.

One of the most distinctive characteristics is its use of a hardcoded mutex named "hsfjuukjzloqu28oajh727190" to prevent multiple instances from running simultaneously. This anti-reentry mechanism is standard among Conti-derived ransomware families and provides a reliable indicator of compromise for defenders.

The ransomware also contains notable flaws that suggest rushed development or incomplete testing. Due to builder misconfiguration, the malware often encrypts its own ransom notes, making them inaccessible to victims. Additionally, the wallpaper-changing function works on Windows 10 but fails on Windows 11, indicating compatibility issues or incomplete adaptation to newer operating systems.

Use ANY.RUN free for 14 days

Try the full power of interactive analysis

Start your free trial

DEVMAN Ransomware Victimology

DEVMAN primarily targets mid-to-large enterprises in non-Western markets, with a heavy focus on Asia (e.g., Thailand, Indonesia) and Africa (e.g., healthcare and government sectors), though it has expanded to Europe, Latin America, and North America.

The group favors critical infrastructure, including transportation, social security funds, and media outlets, as well as healthcare providers (excluding pediatric cases to avoid backlash).

Early victims included government agencies and funds with massive data hauls (e.g., 2.5 TB exfiltrated from a national social security entity via compromised RDP). By May 2025, DevMan claimed 13 victims in a single month, rivaling top-tier groups, and has since amassed nearly 120 confirmed cases. Sectors hit hardest include manufacturing, finance, and public services, with ransoms scaling from $50,000 for smaller entities to over $2.5 million for high-revenue targets, often auctioned if unpaid.

How DEVMAN Ransomware Functions

The group functions as an affiliate across multiple Ransomware-as-a-Service platforms while also conducting direct attacks with their proprietary toolset.

Primary infection vectors include compromised Remote Desktop Protocol (RDP) connections. The group gains initial access via VPN and RDP connections, often using stolen credentials or password spraying attacks.

Phishing campaigns serve as another significant attack vector. Exploitation of edge-facing services represents a third major vector. The group exploits VPN gateways and remote management interfaces through vulnerabilities in public-facing applications.

DEVMAN implements faster lateral movement via Group Policy Object deployment from compromised domain controllers. This allows rapid propagation across enterprise environments once administrative credentials are obtained.

DEVMAN’s evolution includes the use of various tools for reconnaissance and privilege escalation. BloodHound is deployed for Active Directory attack path visualization, while SoftPerfect Network Scanner facilitates network reconnaissance. These tools enable sophisticated understanding of the target environment before encryption begins.

The ransomware uses hybrid cryptography combining AES-256 symmetric encryption for speed with RSA-2048 asymmetric encryption for key protection. This combination ensures both rapid file processing and cryptographic security that prevents decryption without the attacker's private key.

The execution flow begins with environment reconnaissance. DEVMAN enumerates all accessible drives and network shares, building a comprehensive target list. The malware specifically probes for SMB shares within local network ranges, attempting to spread laterally to maximize impact across the organization.

Persistence mechanisms leverage the Windows Restart Manager API in a manner characteristic of Conti-derived malware. The ransomware logs metadata for critical files, identifies processes locking those files, and forces their termination or restart to gain encryption access. Registry entries are created under the Restart Manager session key, then rapidly deleted to minimize forensic traces.

Process execution follows a carefully orchestrated sequence. The malware first disables security tools where possible, deletes shadow copies to prevent recovery, and empties recycle bins. Only then does encryption begin, with the ransomware processing files according to the selected mode while avoiding system-critical extensions that would render the machine unbootable.

The ransom note generation process contains a critical flaw. Due to a builder flaw, the ransomware encrypts its own ransom note files, renaming them deterministically to e47qfsnz2trbkhnt.devman. This means victims may not receive payment instructions, effectively severing the communication channel needed for ransom negotiation.

Network activity is deliberately minimal. Unlike many modern ransomware variants that maintain constant communication with command servers, DEVMAN operates in an almost completely offline mode. The only network traffic involves SMB scanning for lateral movement opportunities, making network-based detection more challenging.

Sandbox Analysis of a DEVMAN Sample

ANY.RUN’s Interactive Sandbox provides isolated, instrumented environments where security researchers and analysts can safely execute suspicious files without risking production systems.

View a DEVMAN sample analysis

DEVMAN Sandbox analysis DEVMAN’s processes and artifacts in the Interactive Sandbox

An analyst can view the ransomware’s process tree mapped to MITRE ATT&CK Matrix, explore connections, files, scripts, registry changes and more.

DEVMAN process tree DEVMAN’s processes

For example, one can view DEVMAN’s ransom note with a reference to DragonForce:

DEVMAN ransom note Ransom note with decryption instructions

Or observe DEVMAN converting filenames via a specific function and adding a .devman extension.

DEVMAN encrypts and renames files DEVMAN encrypts and renames files

The ransomware scans for SMB shares for lateral movement.

DEVMAN network activity DEVMAN network activity

Examples of the Most Successful DEVMAN Ransomware Attacks

DEVMAN’s most impactful strikes highlight its efficiency in high-stakes sectors:

  • French Transport Authority (April 2025): Initial claim via X (formerly Twitter), with full network encryption disrupting operations; exact ransom undisclosed but marked DEVMAN’s debut as a standalone threat.

  • Thai Media Outlet (May 2025): Exfiltrated 170 GB using a customized encryptor with ".devman" extension; screenshots showed domain controller access and GPO deployment, with data offered for single-buyer sale post-encryption.

  • National Social Security Fund (Early 2025): Compromised via RDP, yielding 2.5 TB exfiltration; ransom demand hit $2.5 million, showcasing DevMan's scale against critical public services.

  • Abdulhadi Hospital and Easter Seals (December 2025): Recent healthcare hits with 246 GB and 236 GB stolen, respectively; ransoms of $350k and $90k, emphasizing permissible targeting of adult medical data.

Gathering Threat Intelligence on DEVMAN Malware

By querying suspicious files or network indicators against a vast database of malware samples analyzed in the Sandbox by over 15K SOCs worldwide, security teams can quickly determine whether observed activity relates to known DEVMAN campaigns.

You can also use Threat Intelligence Lookup to find more live DEVMAN samples and indicators by searching a signature IOC like the mutex this ransomware usually features:

syncObjectName:"hsfjuukjzloqu28oajh727190" and filePath:"devman"

DEVMAN mutex lookup DEVMAN mutex in TI Lookup

Integrate ANY.RUN’s threat intelligence solutions in your company

Contact us

Conclusion

DEVMAN exemplifies the ransomware ecosystem's resilience, recycling Conti-era code into a profitable RaaS machine that preys on global enterprises with surgical precision. From its affiliate roots to independent empire-building, it underscores the need for vigilant, layered defenses amid code-sharing cartels. As attacks proliferate (now over 120 victims), organizations must invest in TI, sandboxes, and resilience to outpace these digital extortionists, turning potential catastrophes into manageable risk.

Trial TI Lookup to start gathering actionable threat intelligence on emerging malware: just sign up to ANY.RUN.

HAVE A LOOK AT

AsyncRAT screenshot
AsyncRAT
asyncrat
AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.
Read More
PhantomEnigma screenshot
PhantomEnigma
phantomenigma
PhantomEnigma (also known as Operation Phantom Enigma) is a sophisticated crimeware operation primarily targeting banking organizations and the public sector in Brazil. The campaign is characterized by its strategic abuse of compromised legitimate infrastructure, specifically Brazilian government (.gov.br) portals and municipal websites, to host and distribute malicious payloads.
Read More
BTMOB RAT screenshot
BTMOB RAT
btmob
BTMOB RAT is a remote access Trojan (RAT) designed to give attackers full control over infected devices. It targets Windows and Android endpoints. Its modular structure allows operators to tailor capabilities, making it suitable for espionage, credential theft, financial fraud, and establishing long-term footholds in corporate networks.
Read More
Grandoreiro screenshot
Grandoreiro
grandoreiro
Grandoreiro is a Latin American banking trojan first observed in 2016. It targets mostly Spanish-speaking countries, such as Brazil, Spain, Mexico and Peru. This malware is operated as a Malware-as-a-Service (MaaS), which makes it easily accessible for cybercriminals. Besides, it uses advanced techniques to evade detection.
Read More
Godfather screenshot
Godfather
godfather
The Godfather malware is an Android banking Trojan capable of bypassing MFA that targets mobile banking and cryptocurrency applications. Known for its ability to evade detection and mimic legitimate software, it poses a significant threat to individuals and organizations by stealing sensitive data and enabling financial fraud.
Read More
SSLoad screenshot
SSLoad
ssload
SSLoad is a malicious loader or downloader that is used to infiltrate target systems through phishing emails, perform reconnaissance and transmit it back to its operators delivering malicious payloads. To avoid detection, SSLoad employs various encryption methods and delivery techniques highlighting its versatile nature and complexity. It is believed to be a part of Malware-as-a-Service (MaaS) operation given its diverse delivery methods and implemented techniques.
Read More